Chapter 7: Docker Volumes, Networks and Compose
7.5 Env files — never commit real secrets
Create a .env next to the Compose file for local labs. Compose loads it for ${POSTGRES_PASSWORD} substitution.
# .env — LOCAL LAB ONLY — add to .gitignore
POSTGRES_PASSWORD=lab-only-change-me
# .gitignore excerpt
.env
.env.*
!.env.example
Ship an .env.example with fake placeholders so teammates know which keys exist — without real passwords.
| Do | Do not |
|---|---|
.env gitignored |
Commit production passwords |
| Rotate if a lab password leaked to a public repo | Reuse the same lab password everywhere forever |
| Use platform secrets in CI later (Actions chapter) | Paste cloud keys into YAML |
Ravindra Bagale's Tip
Khup students .env git add . ne push kartat. git status pahile — .env red/untracked rahila pahije. Commit zala tar password rotate kara. Dhyan rakho!
Practice task
Write a three-line .env.example for badge API Compose (password + optional APP_ENV) using clearly fake values only.